CVE-2025-47601 Details
Description
Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Privilege Escalation.This issue affects MaxiBlocks: from n/a through <= 2.1.0.
A missing authorization vulnerability in the WordPress MaxiBlocks plugin, affecting versions through 2.1.0, allows for privilege escalation. This vulnerability could enable a low-privileged user to gain higher privileges, potentially leading to full control of the website.
Users of the WordPress MaxiBlocks plugin are advised to update to version 2.1.0 or later. For those unable to update immediately, Patchstack has issued a virtual patch that blocks attacks targeting this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 7, 2025CISA-ADP
Assessed Jun 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Christiaan Pieterse MaxiBlocks | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | CVE Modified | [email protected] |
| Apr 1, 2026 | CVE Modified | [email protected] |
| Jun 7, 2025 | New CVE Received | [email protected] |
Volerion